Cisco Certified CyberOps Associate (200-201) Cert Prep: 1 Security Concepts
2h 23mIntermediate2021-05-06
Authors

Lisa Bock
Security ambassador with a broad range of IT skills and knowledge
Course details
In this course, instructor Lisa Bock helps you prepare for the Cisco CBROPS exam. Lisa covers the principles of a defense-in-depth strategy, to ensure the confidentiality, availability, and integrity of a system. Lisa outlines today’s threats and threat actors, and explores the relationship between risk, threat, vulnerability, and exploit. She helps you understand the metrics that make up the Common Vulnerability Scoring System. She reviews access control models and stresses the importance of employing the principle of least privilege. Lisa covers the challenges of complex environments in monitoring traffic and describes how using SIEM, SOAR, and log management helps consolidate information. She summarizes security deployments, such as network and endpoint systems. Lisa compares anti-malware applications, outlines the benefits of using threat intelligence, and concludes by describing methods you can use to manage risks and prevent data loss.
Skills covered
Incident ResponseCert PrepCybersecurity
Concepts
Introduction
- Defending the network
- Prepare for Cisco CBROPS exam
- Setting up your test environment
Exploring Security Concepts
- Recognizing today s threats
- Understanding the threat actor
- Outlining the CIA triad
- Having zero trust
- Exploring risk
- Analyzing risk
- Challenge - Overview of malware
- Solution - Overview of malware
Assessing Vulnerabilities
- Using the CVSS
- Interpreting CVSS metric groups
- Understanding the CVE and the NVD
- Challenge - Temporal metric group
- Solution - Temporal metric group
Controlling Access
- Using the principle of least privilege
- Defining access control
- Comparing access control models
- Summarizing triple-A security
- Verifying authentication
- Granting authorization
- Accounting and logging activity
- Challenge - Network diagram
- Solution - Network diagram
Understanding the Threats
- Recognizing the complexity of today s environment
- Leveraging threat intelligence
- Hunting threats
- Analyzing malware
- Dissecting malware using reverse engineering
- Detecting anomalies using the sliding window
- Comparing detection methods
- Using five-tuple log analysis
- Monitoring data loss using traffic profiles
Managing Risk and Preventing Data Loss
- Identifying challenges of data visibility
- Comparing security deployments
- Using agentless or agent-based methods
- Utilizing SIEM, SOAR, and log management
- Employing runbook automation
- Exploring Nmap
- Challenge - Using Nmap
- Solution - Using Nmap
Conclusion
- Next steps